Remote job
Senior Penetration Tester
Job details
About this role
Role overview Lead in-depth penetration tests across applications, infrastructure and cloud environments. The role calls for hands-on investigation beyond automated scanning, connecting vulnerabilities into realistic attack paths and helping clients understand how to address them.
Responsibilities - Scope and lead black-box and white-box tests of web applications, APIs, networks, cloud environments and mobile applications. - Create custom exploits, scripts and tools to bypass controls and demonstrate security impact. - Investigate systems manually beyond scanner results and assess how findings combine into broader risks. - Write precise, reproducible reports and advise clients on remediation. - Improve testing methods, tools and quality standards. - Mentor junior testers and review their work.
Requirements - At least four years of penetration testing or offensive security experience, including leading engagements. - Strong knowledge of the OWASP Top 10, network attacks and Active Directory attacks. - Experience assessing at least one of Azure, AWS or GCP. - Proficiency in a scripting language such as Python, Bash or Ruby. - Hands-on experience with Burp Suite, Nmap, Metasploit, BloodHound or comparable tools. - OSCP or equivalent practical skill, plus strong technical writing in English.
Nice to have - Source-code review experience. - OT/ICS, mobile or thick-client testing experience. - Public Burp or Ghidra extensions, CVEs or CTF placements.